Skip to content

Commit

Permalink
Use a list for Hegel trusted proxy configuration (#34)
Browse files Browse the repository at this point in the history
We found a pattern that works well and is proven out in Boots. This aligns trusted proxy configuration with the approach in Hegel.

Closes #29
  • Loading branch information
mergify[bot] authored Feb 7, 2023
2 parents d8fdcca + 898fef0 commit f72bb4d
Show file tree
Hide file tree
Showing 2 changed files with 5 additions and 2 deletions.
2 changes: 1 addition & 1 deletion tinkerbell/hegel/templates/deployment.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -33,7 +33,7 @@ spec:
{{- end }}
env:
- name: HEGEL_TRUSTED_PROXIES
value: {{ required "missing trustedProxies" .Values.trustedProxies | quote }}
value: {{ required "missing trustedProxies" ( join "," .Values.trustedProxies | quote ) }}
{{- range $i, $env := .Values.env }}
- name: {{ $env.name | quote }}
value: {{ $env.value | quote }}
Expand Down
5 changes: 4 additions & 1 deletion tinkerbell/hegel/values.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,4 @@
deploy: true
trustedProxies: ""
name: hegel
image: quay.io/tinkerbell/hegel:v0.10.1
imagePullPolicy: IfNotPresent
Expand All @@ -18,3 +17,7 @@ resources:
memory: 64Mi
roleName: hegel-role
roleBindingName: hegel-rolebinding

# Trusted proxies defines a list of IP or CIDR ranges that are allowed to set the X-Forwarded-For
# header. This typically requires all Pod CIDRs in the cluster.
trustedProxies: []

0 comments on commit f72bb4d

Please sign in to comment.